US11449243B2ExpiredUtilityA1

System and method to secure a computer system by selective control of write access to a data storage medium

Assignee: EIGHTH STREET SOLUTIONS LLCPriority: Dec 1, 2005Filed: Jun 17, 2021Granted: Sep 20, 2022
Est. expiryDec 1, 2025(expired)· nominal 20-yr term from priority
Inventors:John Safa
G06F 2221/2115G06F 3/0676H04L 63/101G06F 3/0622G06F 3/0659G06F 21/554G06F 21/564G06F 2221/2141G06F 21/52
65
PatentIndex Score
0
Cited by
9
References
10
Claims

Abstract

A system and method of securing a computer system by controlling write access to a storage medium by monitoring an application; detecting an attempt by the application to write data to said storage medium; interrogating a rules database in response to said detection; and permitting or denying write access to the storage medium by the application in dependence on said interrogation.

Claims

exact text as granted — not AI-modified
What is claimed is as follows: 
     
       1. In a computer comprising a storage medium and an application running on said computer, a method of controlling write access to said storage medium by said application comprising:
 detecting a first attempt by the application to write data to said storage medium of a first computer; 
 in response to said first write attempt, attempting to retrieve a permission value from a database comprised of data elements encoding at least one permission value associated with one or more applications; 
 in a case that no permission value for the running application is found in the database, transmitting to a central server operatively connected to the first computer and to at least one additional computer, a query comprised of an indicia of identity associated with said running application; 
 receiving from said central server, data that represents the collective response of the user of the at least one additional computer to requests by the same application running on said at least one additional computer to access the storage medium that comprises said at least one additional computer; 
 encrypting or compressing a copy of said data received from the central server; 
 saving all or part of the encrypted or compressed copy of said data received from the central server to said storage medium; 
 detecting a second attempt by the application to write data to said storage medium of a first computer; 
 in response to said second write attempt, testing an integrity of the second write attempt against the encrypted or compressed copy of said data received from the central sever; 
 in the case of testing the integrity of the second write attempt against the encrypted or compressed copy of said data received from the central sever, detecting a defection of a destroyed application or data from the second attempt by the application to write data; 
 in the case of a detection of a destroyed application or data for the running application is found, transmitting to a vault system operatively connected to the first computer, a request to decrypt or decompress said encrypted or compressed copy associated with said running application; 
 receiving from said vault system, all or part of the encrypted or compressed copy of said data requested from the central server; 
 in response to said receiving all or part of the encrypted or compressed copy of said data requested from the central server, replacing the detected destroyed application or data of the running application from the received all or part of the encrypted or compressed copy of data in the vault system. 
 
     
     
       2. The method of  claim 1  further comprising displaying on an user interface of said computer, graphical forms representative of said collective response data. 
     
     
       3. The method of  claim 1  where the data that represents the collective response data includes a percentage of other computer users who have approved the application writing to the storage medium associated with their respective at least one additional computer. 
     
     
       4. The method of  claim 1  where the data that represents the collective response data includes a number which is the number of other users that have approved the application writing to the storage medium associated their respective at least one additional computer. 
     
     
       5. The method of  claim 1  where the detection of a destroyed application or data for the running application includes detection of a malicious code. 
     
     
       6. The method of  claim 1  where the detection of a destroyed application or data for the running application includes detection of a destroyed application or data by a virus. 
     
     
       7. The method of  claim 1  where the detection of a destroyed application or data for the running application includes detection of a destroyed application or data by a troj an virus. 
     
     
       8. The method of  claim 1  where the detection of a destroyed application or data for the running application includes detection of a destroyed application or data by a spyware. 
     
     
       9. In a computer comprising a storage medium and an application running on said computer, a method of controlling write access to said storage medium by said application comprising:
 detecting an attempt by the application to write data to said storage medium; 
 in response to said write attempt, attempting to retrieve a permission value from a database comprised of data elements encoding at least one permission value associated with one or more applications; 
 in a case that no permission value for the running application is found, transmitting to a central server operatively connected to the computer a query comprised of an indicia of identity associated with said running application; 
 receiving from said central server information collective response data of at least one other computer user's to the request by the same application running on said other computer user's computers to access the storage medium that comprises said at least one other computer user's computers; 
 receiving from said central server information transmitted to said central server, said information comprising other user's critique of said at least one other computer user's response; 
 encrypting or compressing a copy of said data received from the central server; 
 saving all or part of the encrypted or compressed copy of said data received from the central server to said storage medium; 
 detecting a second attempt by the application to write data to said storage medium of a first computer; 
 in response to said second write attempt, testing an integrity of the second write attempt against the encrypted or compressed copy of said data received from the central sever; 
 in the case of testing the integrity of the second write attempt against the encrypted or compressed copy of said data received from the central sever, detecting a defection of a destroyed application or data from the second attempt by the application to write data; 
 in the case of a detection of a destroyed application or data for the running application is found, transmitting to a vault system operatively connected to the first computer, a request to decrypt or decompress said encrypted or compressed copy associated with said running application; 
 receiving from said vault system, all or part of the encrypted or compressed copy of said data requested from the central server; 
 in response to said receiving all or part of the encrypted or compressed copy of said data requested from the central server, replacing the detected destroyed application or data of the running application from the received all or part of the encrypted or compressed copy of data in the vault system. 
 
     
     
       10. In a computer comprising a storage medium and an application running on said computer, a method of controlling write access to said storage medium by said application comprising:
 detecting an attempt by the application to write data to said storage medium; 
 in response to said write attempt, attempting to retrieve a permission value from a database comprised of data elements encoding at least one permission value associated with one or more applications; 
 in a case that no permission value for the running application is found, transmitting to a central server operatively connected to the computer a query comprised of an indicia of identity associated with said running application; 
 receiving from said central server information collective response data of at least one other computer user's to the request by the same application running on said other computer user's computers to access the storage medium that comprises said at least one other computer user's computers; 
 receiving from said central server information transmitted to said central server, said information comprising other user's critique of said at least one other computer user's response; 
 encrypting or compressing a copy of said data received from the central server; 
 saving all or part of the encrypted or compressed copy of said data received from the central server to said storage medium; 
 detecting a second attempt by the application to write data to said storage medium of a first computer; 
 in response to said second write attempt, testing an integrity of the second write attempt against the encrypted or compressed copy of said data received from the central sever; 
 in the case of testing the integrity of the second write attempt against the encrypted or compressed copy of said data received from the central sever, detecting a defection of a destroyed application or data from the second attempt by the application to write data; 
 in the case of a detection of a destroyed application or data for the running application is found, transmitting to a vault system operatively connected to the first computer, a request to decrypt or decompress said encrypted or compressed copy associated with said running application; 
 receiving from said vault system, all or part of the encrypted or compressed copy of said data requested from the central server; 
 in response to said receiving all or part of the encrypted or compressed copy of said data requested from the central server, replacing the detected destroyed application or data of the running application from the received all or part of the encrypted or compressed copy of data in the vault system; 
 in the case of replacing the detected destroyed application or data of the running application from the received all or part of the encrypted or compressed copy of data in the vault system, detecting a fully replaced destroyed application or data of the running application from the received all or part of the encrypted or compressed copy of data in the vault system; 
 in response to detecting a fully replaced destroyed application or data of the running application from the received all or part of the encrypted or compressed copy of data in the vault system, launching the said second write attempt.

Join the waitlist — get patent alerts

Track US11449243B2 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.